Hildegard is a Linux cryptojacking malware associated with TeamTNT and designed for cloud-native and containerized environments, particularly Kubernetes. It has been used against exposed Kubernetes infrastructure, including anonymously accessible kubelets and related container services, to deploy cryptocurrency-mining workloads at scale. The malware is closely tied to TeamTNT’s broader tradecraft of abusing misconfigured cloud services for monetization and post-compromise expansion.
Hildegard combines cryptomining with interactive post-exploitation and credential-harvesting behavior. It has been observed searching compromised environments for SSH keys, Docker credentials, and Kubernetes service account tokens, indicating an intent to expand access within container clusters and adjacent cloud infrastructure. It also performs internal reconnaissance by scanning Kubernetes networks for additional kubelets. For command and control, Hildegard has established tmate sessions, giving operators live remote access to compromised environments.
The malware incorporates multiple defense-evasion measures. Reported behaviors include decrypting ELF payloads with AES, modifying DNS resolver settings to reduce the effectiveness of DNS-based monitoring, and deleting scripts after execution to limit forensic visibility. TeamTNT activity associated with Hildegard has also used container-breakout tooling such as BotB, which exploits CVE-2019-5736, to escape containers and gain deeper host access.
Hildegard is best understood as part of TeamTNT’s evolution from opportunistic cloud cryptojacking into more capable Linux and Kubernetes-focused intrusion activity. Its targeting aligns with organizations operating exposed or weakly secured container orchestration infrastructure, especially cloud-hosted environments where compromised compute resources can be rapidly converted into illicit cryptocurrency mining capacity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Hildegard has used the BOtB tool which exploits CVE-2019-5736.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
"Hildegard has searched for SSH keys, Docker credentials, and Kubernetes service tokens." / "TeamTNT has searched for unsecured AWS credentials and Docker API credentials." | "...extract credentials from configuration or support files." / "...search for files containing passwords." / "...obtained administrative credentials by browsing through local files..."
Ebury has intercepted unencrypted private keys as well as private key pass-phrases. Hildegard has searched for private keys in .ssh. jRAT can steal keys for VPNs and cryptocurrency wallets. Kinsing has searched for private keys. Machete has scanned and looked for cryptographic keys and certificate file extensions. TeamTNT has searched for unsecured SSH keys. Troll Stealer collects all data in victim .ssh folders by creating a compressed copy that is subsequently exfiltrated.
AADInternals can gather unsecured credentials for Azure AD services, such as Azure AD Connect, from a local machine... Agent Tesla has the ability to extract credentials from configuration or support files... APT33 has used a variety of publicly available tools like LaZagne to gather credentials.
The content repeatedly describes threat actors and malware performing network scanning, port scanning, service enumeration, OS fingerprinting, and identifying open ports/services across victim environments.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
Hildegard has established tmate sessions for C2 communications. TeamTNT has established tmate sessions for C2 communications.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments. BlackByte has used tools such as AnyDesk in victim environments. Carbanak used legitimate programs such as AmmyyAdmin and Team Viewer for remote interactive C2 to target systems.
Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. One common purpose for Compute Hijacking is to validate transactions of cryptocurrency networks and earn virtual currency.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cryptojacking malware targeting Kubernetes, referenced in the additional resources section.
Malware used in TeamTNT’s Kubernetes-focused campaign to compromise exposed kubelet environments, deploy mining activity, and maintain access using reverse shell/Tsunami/tmate-related tooling.
Custom cryptojacking malware developed by TeamTNT.
A TeamTNT cryptojacking malware targeting Kubernetes, mentioned as a prior TeamTNT operation whose behaviors were not present in the newer WatchDog scripts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.